Cyber Posture

CWE · MITRE source

CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Abstraction: Base · CVEs in our corpus: 4,105

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SC-27Platform-independent ApplicationsSCPlatform-independent managed code eliminates the need for unchecked native buffer copies that are the root cause of classic buffer overflows.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-7269 KEV9.69.80.94412017-03-27
CVE-2020-15999 KEV9.59.60.92912020-11-03
CVE-2016-10174 KEV9.49.80.91072017-01-30
CVE-2019-11043 KEV9.48.70.94052019-10-28
CVE-2016-6366 KEV9.28.80.91212016-08-18
CVE-2007-5659 KEV9.17.80.92872008-02-12
CVE-2018-6789 KEV9.19.80.86442018-02-08
CVE-2016-0099 KEV9.07.80.89962016-03-09
CVE-2013-1331 KEV8.97.80.88922013-06-12
CVE-2020-15069 KEV8.99.80.82572020-06-29
CVE-2013-0641 KEV8.87.80.87962013-02-14
CVE-2022-37055 KEV8.89.80.80482022-08-28
CVE-2023-41064 KEV8.77.80.85352023-09-07
CVE-2006-2492 KEV8.28.80.74082006-05-20
CVE-2010-2572 KEV8.07.80.74722010-11-10
CVE-2022-374347.59.80.92742022-08-05
CVE-2019-167247.19.80.85732019-09-24
CVE-2020-80127.09.80.83892020-02-18
CVE-2017-152226.99.80.81592017-10-24
CVE-2019-122556.99.80.82382019-08-09
CVE-2020-119846.79.80.79682020-08-07
CVE-2010-53336.69.80.77022019-09-13
CVE-2009-01826.58.80.79022009-01-20
CVE-2017-6862 KEV6.59.80.43112017-05-26
CVE-2019-125186.59.80.74842019-12-02